Results arrive back from providers automatically. Each provider needs one address registered in its own dashboard, which the User Verification screen shows you.
Results that cannot be trusted are refused
ActiveManage fails closed at every step. A result is rejected if it comes from an unknown or disabled provider, if no signing secret has been configured, if the signature does not verify, or if the message is implausibly large. A missing secret is never treated as "skip the check".
The two affiliation providers go further and re-read the result from their own service before believing it, so a forged message cannot create a pass even if a secret leaked.
Users complete a check but nothing happens
Checks stuck at awaiting user after the customer has finished almost always mean results are not getting back:
- Is the address registered at the provider, exactly as shown on the screen?
- Is the signing secret entered, and current? Rotating a secret at the provider without updating it here breaks every result, silently. This is the most common cause.
- Is your site reachable from the internet, and not behind an IP restriction that excludes the provider?
- Check the Verification Events record. A webhook event proves the result arrived; none means it never did.
- Check the Error Log — every rejection is logged with its reason.
Other common problems
- Every Onfido call fails — the region setting does not match the region your Onfido account was created in.
- A type will not enable — the screen states the reason.
- Internal links never arrive — check the chosen e-mail account and the E-mail Log.
- "My domain should qualify" — check the wildcard:
*.ac.ukdoes not match a bareac.uk.